Every conversation about AI in an Irish practice arrives at the same place within about ninety seconds: what happens to my clients’ information?
It is the right instinct, and it deserves a better answer than the two most common ones. “It’s fine, everyone’s using it” is not an answer. Neither is “never touch it”. Both skip the work of actually understanding where the risk sits.
Where the risk actually is
The risk is rarely the model itself. It is almost always one of three things:
Data leaving your control
Information typed into a consumer-tier tool may be retained and used to improve the service. That is a disclosure you did not sanction and probably cannot undo. This is the headline risk and also the easiest to eliminate.
Data going somewhere you cannot account for
Storage location, retention period, sub-processors, who at the provider can access what. If you cannot answer these, you cannot answer a client who asks.
Data going in that never needed to
The most overlooked one. A substantial share of genuinely useful AI work in a practice does not require identifiable client information at all. Drafting a standard letter structure, summarising a statutory provision, building a checklist, turning notes into a first-draft attendance — much of this runs on structure and precedent rather than on the client’s name and PPSN.
Before pasting anything, ask: does the tool need this detail to do the job? Very often the answer is no, and the confidentiality question dissolves before it needs answering.
The controls that make a workflow defensible
A defensible AI setup in a solicitor’s practice generally has these features. None of them are exotic.
- Business or enterprise tier, never free consumer. The commercial terms are the substance of the protection.
- Training on your data explicitly disabled — verified in settings, not assumed.
- A data processing agreement in place where personal data is involved, with the provider as processor and your practice as controller.
- Retention configured deliberately rather than left at default.
- A written internal position on what may and may not be put into an AI tool. One page is enough. It matters more that it exists and that staff have read it than that it is long.
- Solicitor review before anything leaves the practice. Non-negotiable, and the thing that makes everything else survivable.
What about the client?
A question that comes up increasingly: do you need to tell clients you use AI?
The safe and professional position is transparency about process without unnecessary alarm. You are not obliged to itemise every piece of software your practice uses, and clients do not expect a list. But a practice that uses AI materially in producing client work should be comfortable saying so if asked, and should be able to explain the supervision arrangement in a sentence: AI prepares, a solicitor reviews and signs off, and confidentiality controls are in place.
If that sentence would embarrass you, the setup needs work rather than concealment.
Professional obligations do not change
This is the part that gets lost in the noise. Adopting AI does not create a new category of professional duty and does not dilute an existing one. Your obligations on confidentiality, competence and supervision are exactly what they were. The tool is new; the standard is not.
That is actually reassuring, because it means you already know how to evaluate this. You would not send an unreviewed draft from a trainee to a client. The same instinct, applied to AI output, gets you most of the way to a defensible practice.
The short version
Confidentiality is manageable, but only deliberately. Business tier, training off, a processing agreement, a one-page internal policy, and a solicitor reviewing before anything goes out. Get those five right and the confidentiality objection stops being the thing that blocks adoption.
See where the hours are going
A free 15-minute AI admin audit. We look at your actual week and tell you which tasks are worth automating — and which aren’t.
Book Your Free Audit →